Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed
ID: d1c3b63d-b236-510a-8bed-79891b671742
STIX ID: report--d1c3b63d-b236-510a-8bed-79891b671742
Feed Name: Bleeping Computer
A critical MongoDB vulnerability named MongoBleed (CVE-2025-14847) allows unauthenticated attackers to trigger zlib-based decompression memory leaks and exfiltrate in-memory secrets (credentials, API/cloud keys, tokens, PII). A public PoC is available and active exploitation has been observed; Censys found ~87,000 potentially vulnerable instances and cloud telemetry shows widespread exposure. MongoDB released patches and recommends updating (or disabling zlib) while detection tools and log parsers have been published to hunt for exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
